๐ซ๐ท
dynamix
2026-09-08 21:50:22
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Sklurk
2026-09-06 06:47:49
(2 weeks ago)
Web App Attack
Web App Attack
Anonymous
2026-09-05 09:46:27
(2 weeks ago)
45.3.49.228 - - [05/Sep/2026:11:46:25 +0200] "GET http://farmretreat.thempandes.com:80/wp-includes/w ...
show more
45.3.49.228 - - [05/Sep/2026:11:46:25 +0200] "GET http://farmretreat.thempandes.com:80/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
45.3.49.228 - - [05/Sep/2026:11:46:26 +0200] "GET http://farmretreat.thempandes.com:80/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
45.3.49.228 - - [05/Sep/2026:11:46:26 +0200] "GET http://farmretreat.thempandes.com:80/web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
45.3.49.228 - - [05/Sep/2026:11:46:27 +0200] "GET http://farmretreat.thempandes.com:80/wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Geck
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
SX Communications
2026-09-05 03:56:25
(2 weeks ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 45.3.49.228: traffic from this addr ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 45.3.49.228: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐จ๐ญ
SOC [GOLINE SA]
2026-09-03 10:58:20
(2 weeks ago)
[RoutePulse | 2026-09-03T10:58:20Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.49.228 ...
show more
[RoutePulse | 2026-09-03T10:58:20Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.49.228 ยท AS200373 3xK Tech GmbH ยท United States
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ธ๐ช
OnTheEdge
2026-09-03 00:07:05
(2 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ธ๐ช
OnTheEdge
2026-09-03 00:07:05
(2 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2026-09-01 05:22:18
(2 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-08-03 00:10:25
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-16 10:08:51
(2 months ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-23 04:56:00
(2 months ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-20 00:01:05
(3 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 03:25:13
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 22:25:05.247343 2026] [security2:error] [pid 23085:tid 23085] [client 45.3.49.228:55845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artbytracyjane.com"] [uri "/.git/config"] [unique_id "aY1IEast29hyn9Zj9DfYaQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 17:43:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 12:43:21.992455 2026] [security2:error] [pid 4737:tid 4737] [client 45.3.49.228:9935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/api/.env"] [unique_id "aYtuOTMvXX7wAxVJzRFiPgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 15:34:03
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:33:57.240247 2026] [security2:error] [pid 30071:tid 30071] [client 45.3.49.228:37373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.net"] [uri "/admin/.env"] [unique_id "aYtP5ZE82qGRLE_oIPdQBQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack